Lucene search

K
osvGoogleOSV:GHSA-PG2W-X9WP-VW92
HistoryMay 13, 2022 - 1:11 a.m.

Python Requests Session Fixation

2022-05-1301:11:23
Google
osv.dev
12
python
requests
session fixation
security
attack

AI Score

5.5

Confidence

High

EPSS

0.016

Percentile

87.5%

The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect.

AI Score

5.5

Confidence

High

EPSS

0.016

Percentile

87.5%